Home/Product/azure access blu ic4 firmware
Product

azure access blu ic4 firmware

39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-12603
< 1.20
/etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12602
< 1.20
/etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12601
< 1.20
Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
7.5HIGH
CVE-2025-12600
< 1.20
Web UI Malfunction when setting unexpected locale via API.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12599
< 1.20
Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: throug
9.8CRITICAL
CVE-2025-12554
< 1.20
Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12553
< 1.20
Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12552
< 1.20
Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12517
< 1.20
Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
5.3MEDIUM
CVE-2025-12516
< 1.20
Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
9.8CRITICAL
CVE-2025-12515
< 1.20
Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
9.8CRITICAL
CVE-2025-12479
< 1.20
Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: throu
8.8HIGH
CVE-2025-12478
< 1.20
Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
9.8CRITICAL
CVE-2025-12477
< 1.20
Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
9.8CRITICAL
CVE-2025-12476
< 1.20
Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
9.8CRITICAL
CVE-2025-12425
< 1.20
Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
7.8HIGH
CVE-2025-12424
< 1.20
Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
9.8CRITICAL
CVE-2025-12423
< 1.20
Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
7.5HIGH
CVE-2025-12422
< 1.20
Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2
9.8CRITICAL
CVE-2025-12365
< 1.20
Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
5.3MEDIUM
CVE-2025-12364
< 1.20
Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12363
< 1.20
Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
7.5HIGH
CVE-2025-12285
< 1.20
Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12284
< 1.20
Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: t
6.1MEDIUM
CVE-2025-12278
< 1.20
Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
6.5MEDIUM
CVE-2025-12275
< 1.20
Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12221
< 1.20
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
8.8HIGH
CVE-2025-12220
< 1.20
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12219
< 1.20
Vulnerable Components in Azure Access OS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.8CRITICAL
CVE-2025-12218
< 1.20
Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.1CRITICAL
CVE-2025-12217
< 1.20
SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
9.1CRITICAL
CVE-2025-12216
< 1.20
Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19
5.5MEDIUM
CVE-2025-12176
< 1.20
Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affect
9.8CRITICAL
CVE-2025-12114
< 1.20
Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU
5.5MEDIUM
CVE-2025-12104
< 1.20
Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4
9.8CRITICAL
CVE-2025-12031
< 1.20
HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascrip
5.3MEDIUM
CVE-2025-12001
< 1.20
Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: th
6.1MEDIUM
CVE-2025-11925
< 1.20
Incorrect Content-Type header in one of the APIs (text/html instead of application/json) replies may potentially allow injecti
6.1MEDIUM
CVE-2025-11832
< 1.20
Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin